| ▲ | vladvasiliu 2 hours ago | |
You can have automatic unlock with tpm2, with or without a pin, in addition to passphrase, file, fido2, pkcs#11 cert, or whatever else is supported by luks. I've been using this for a few years now, and never had an issue. https://wiki.archlinux.org/title/Systemd-cryptenroll > Imagine a motherboard failure and boom there goes my entire disk. You can also set a long-ass key in addition to the other methods, and back it up somewhere safe. It works the same as bitlocker: you have key which can decrypt the drive without external help from a TPM in case something goes wrong. | ||